3CX DLL-Sideloading attack: What you need to know
I upgraded to the soft-release candidate today. I had to reset my AP-10 since the previous beta caused it to go into the reboot loop.
Now my access point is generating alot of extra logs, see below. This is wasting alot of space and is building rather quickly....
016:03:17-16:33:25 10.1.0.101 download_ca: CA fingerprint overwritten by TA 2016:03:17-16:33:25 10.1.0.101 download_ca: No trusted fingerprint found in certificate chain HUB. 2016:03:17-16:33:31 10.1.0.101 download_ca: CA fingerprint overwritten by TA 2016:03:17-16:33:31 10.1.0.101 download_ca: No trusted fingerprint found in certificate chain HUB. 2016:03:17-16:33:37 10.1.0.101 download_ca: CA fingerprint overwritten by TA 2016:03:17-16:33:37 10.1.0.101 download_ca: No trusted fingerprint found in certificate chain HUB. 2016:03:17-16:33:42 10.1.0.101 download_ca: CA fingerprint overwritten by TA 2016:03:17-16:33:42 10.1.0.101 download_ca: No trusted fingerprint found in certificate chain HUB. 2016:03:17-16:33:47 10.1.0.101 download_ca: CA fingerprint overwritten by TA 2016:03:17-16:33:47 10.1.0.101 download_ca: No trusted fingerprint found in certificate chain HUB. 2016:03:17-16:33:52 10.1.0.101 download_ca: CA fingerprint overwritten by TA 2016:03:17-16:33:52 10.1.0.101 download_ca: No trusted fingerprint found in certificate chain HUB. 2016:03:17-16:33:57 10.1.0.101 download_ca: CA fingerprint overwritten by TA 2016:03:17-16:33:58 10.1.0.101 download_ca: No trusted fingerprint found in certificate chain HUB.As you can see it repeats the check every 6 seconds. (10.1.0.101 is my AP-10)
Have you tried rebooting it? It should no longer appear then.
Hi reiner,
I have also upgraded some customers today, this customer has 25 ap's, a mix of AP100, 50, 55, 30 and 10, i have rebooted twice now, but still:
-----
Best regardsMartin
Sophos XGS 2100 @ Home | Sophos v19 Architect
Hi Martin,
are the APs accepted on the UTM and shown as online (after you rebooted them)?
Hi,
Yes they are :-) - hopefully they will stay this way, they have 400 wifi clients this weekend :-O
Eehhh I may have misread the post!!
I rebooted the UTM several times, but I have not walked around in the building, disconnecting the PoE / AC adapters on the Ap's, is that what you wanted?
Yes, after the AP rebooted it will no longer log this message.
Sorry for the confusion :-)
Thanks I will do that :-)
Have a great weekend!